High-performance log parser.
School Purpose Only.
Logstream is a polished educational cybersecurity utility by LayerByte. It focuses on one practical defensive concept and keeps the implementation small enough for students to read, run, and understand.
Large logs are easier to study when parsing is fast, streaming, and focused on the fields that matter.
- Processes logs efficiently
- Keeps memory use reasonable
- Reports matches and statistics
- Clear command-line or local application workflow
- Beginner-readable validation and error handling
- Copy-friendly output for notes, screenshots, and reports
- Conservative behavior designed around local or authorized data
- No exploit code, malware behavior, credential theft, brute forcing, or destructive actions
- Text log files
- Line-oriented event streams
- Go 1.22 or newer
Clone the repository and open the project folder:
git clone https://github.com/LayerByte/logstream.git
cd logstreamThen prepare the project with the standard toolchain:
go mod tidy
go build ./...Start with the help command or the default run command:
go run . --help- Open the project folder.
- Run the help command.
- Provide a small authorized sample input.
- Review the report and compare it with the source code.
Example run:
go run . --helpFiltered log results and summary counts.
Output is intended to be readable in the terminal or application window and easy to copy into a school report or defensive analysis note.
- Use only on systems, files, domains, and data you own or have permission to inspect.
- Treat paths, hostnames, hashes, and log entries as potentially sensitive before sharing output.
- Prefer small sample files when learning how the tool works.
- Do not use the project for unauthorized scanning, exploitation, credential attacks, persistence, evasion, or destructive activity.
- Practice safe input validation and graceful error messages.
- Understand the defensive concept behind the tool.
- Learn how a focused security utility is organized in Go.
- Compare raw input with structured output.
- Build habits around permission, documentation, and responsible testing.
Keep packages focused, use timeouts for network operations, and return clear errors instead of hiding failures.
Suggested checks before publishing changes:
# Run the help command.
# Test with a small non-sensitive sample.
# Confirm errors are clear when input is missing or invalid.- If the command is not found, confirm the required toolchain is installed and available in your PATH.
- If a file cannot be opened, check the path, permissions, and whether another program is locking it.
- If a network-focused check fails, verify the hostname, scheme, connection, and permission to test that endpoint.
- If output looks empty, retry with a smaller known-good sample input.
- Built for education and small authorized workflows, not enterprise monitoring.
- Results depend on operating system permissions, platform APIs, and sample quality.
- Some advanced features are intentionally omitted to keep the code approachable.
- Findings should be reviewed by a human before making security decisions.
This project is for defensive learning, school assignments, and authorized administration. It does not include malware, credential theft, brute-force attacks, exploitation, payload delivery, persistence, bypass functionality, or unauthorized access functionality.
Released under the MIT License.